Skip to main content
Early access: get Pro free for 3 months →
DocsContact
Govern

Prove you're compliant.
Before the auditor asks.

Every finding is automatically tagged to OWASP Top 10, CIS benchmarks, and SOC 2 controls. Every fix is logged. Every gap is visible — so when compliance comes up, you have answers, not panic.

OWASP Top 10·CIS Benchmarks·SOC 2·Audit log on every plan
HZSec — Compliance Overview
HZSec
▣ Scan Center
◈ Assistant
◎ Live Monitor
≡ Audit Log
⚙ Settings
OWASP Top 10
71%
CIS Benchmarks
64%
SOC 2 Controls
58%
Wildcard CORS policy
OWASP A05↩ REC
Debug mode in production
SOC 2 CC6
Exposed AWS access key
OWASP A02↩ REC
Local-first·No cloud upload·Built for developers·Mac & Windows
Why This Matters

Compliance shouldn't be
a fire drill.

Most developers start thinking about compliance when an audit is already scheduled. By then, the gap between where you are and where you need to be is measured in weeks of catch-up work.

Manual framework mapping

Mapping findings to OWASP or SOC 2 by hand takes hours and invites errors. Without automation, it just doesn't get done until someone asks for it.

No audit trail

Auditors want evidence of consistent security practice over time. A single scan the week before an audit doesn't prove that — a timestamped history does.

Recurring issues stay hidden

If the same misconfiguration keeps reappearing across scans, that's a process problem — not just a fix problem. Without history tracking, you can't see it.

How It Works

Compliance context from
the moment you scan.

01

Scan your codebase

Every finding is automatically tagged to OWASP Top 10, CIS benchmark controls, and SOC 2 trust service criteria — no manual mapping required.

02

Review compliance gaps

HZSec shows you a percentage score per framework so you know exactly how far you are from each standard, not just whether findings exist.

03

Fix and track progress

Apply fixes and watch your compliance scores update in real time. The audit log records every change with a timestamp.

04

Generate audit-ready reports

Export a structured report with scan timestamps, finding summaries, severities, and applied fixes — ready to share without additional interpretation.

Everything in the
Govern module.

Automatic framework tagging, gap calculations, fix memory, and a local audit log — designed to help developers stay ahead of compliance, not scramble for it.

OWASP Top 10 mapping

Every finding is tagged to the relevant OWASP Top 10 category. See which parts of the standard you cover, which you don't, and what the fastest path to improvement is.

CIS Benchmark controls

HZSec cross-references findings against CIS benchmark controls for common environments. Know which controls are failing and what a passing configuration looks like.

SOC 2 coverage tracking

HZSec maps findings to SOC 2 trust service criteria — Security, Availability, Confidentiality. See your current coverage and what's holding back a cleaner picture.

Fix memory & recurrence tracking

HZSec tracks whether a finding was fixed and whether it came back. Persistent issues are flagged automatically so you stop patching the same problem twice.

Compliance gap calculations

View your OWASP, CIS, and SOC 2 scores as percentages. Know exactly how far you are from a target threshold — not just whether open findings exist.

Audit log

Every scan, finding severity, fix applied, and rescan result is logged locally with a timestamp. The log is structured, exportable, and yours — no cloud dependency.

What compliance tracking
actually looks like.

Framework scores, finding tags, and recurrence flags — all updated every time you scan. No manual entry, no separate spreadsheet.

HZSec — Audit Log · Compliance
HZSec
▣ Scan Center
◈ Assistant
◎ Live Monitor
≡ Audit Log
⚙ Settings
Framework Coverage
OWASP Top 10
71%
CIS Benchmarks
64%
SOC 2 Controls
58%
Open Findings
Wildcard CORS policy
OWASP A05
Debug mode in production
SOC 2 CC6
TLS verification disabled
CIS 4.3
Exposed AWS access key
OWASP A02
Rate limiting absent
OWASP A04
Why HZSec

What developers used
before this existed.

HZSec isn't a certification platform — it's a developer tool that gives you continuous visibility into compliance posture, so audits don't start from zero.

vs Spreadsheet tracking

Copy findings into a doc, manually assign framework categories, update statuses by hand. Works for five findings. Falls apart at fifty, and never shows trends or recurrence patterns.

HZSec adds
  • Auto-tagged to OWASP/CIS/SOC 2
  • Trend and recurrence tracking
  • Updated on every scan
  • No manual data entry
vs Manual audit prep

A weeks-long scramble before an audit: gather evidence, map controls, explain findings. Most of it happens retrospectively, and the snapshot is already out of date by the time it's submitted.

HZSec adds
  • Continuous, not periodic
  • Evidence logged automatically
  • Audit log ready any time
  • Findings mapped from day one
vs Compliance checklists

Generic checklists give you questions to answer, not visibility into your code. You end up doing the same detective work manually every time — did we disable TLS? Is debug off?

HZSec adds
  • Detects issues directly in code
  • Answers the checklist questions
  • Score-based, not checkbox-based
  • Recurring issues flagged automatically

Common questions
about compliance.

Which frameworks does HZSec map to?

Currently OWASP Top 10, CIS benchmarks for common environments, and SOC 2 trust service criteria. Coverage expands as new scan rules are added.

Is this a replacement for a formal security audit?

No. HZSec is a developer security tool — it helps you find issues, track fixes, and prepare evidence. It doesn't replace a professional audit or issue certifications.

What does the compliance gap percentage mean?

For each framework, HZSec calculates a score based on which controls have passing findings versus open issues. A 71% OWASP score means 71% of the framework's mapped controls pass based on what's been scanned.

How does fix memory and recurrence work?

When you fix a finding and the same issue reappears in a later scan, HZSec marks it as recurring. This flags patterns that need a deeper root-cause fix rather than a surface patch.

Can I export the audit log?

Yes. The audit log can be exported as a structured report. It includes scan timestamps, finding summaries, severities, and applied fixes — formatted to be shareable with an auditor.

Do I need the Team plan for compliance features?

No. Compliance mapping, audit log, gap calculations, and recurrence tracking are available on all plans, including Free. Team adds shared notes and multi-seat audit trails.

Audit log on every plan

Know your compliance posture
before the question is asked.

Download HZSec and get automatic framework tagging, recurrence tracking, and a local audit log from your very first scan.

Free tier free forever · Mac + Windows · 100% local processing